<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I disable Splunk Universals Forwarder input after installing Splunk TA_windows via deployment? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-disable-Splunk-Universals-Forwarder-input-after/m-p/371932#M67512</link>
    <description>&lt;P&gt;Can you change that inputs.conf in the app in the deployment server and then do a splunk reload deploy server?&lt;/P&gt;

&lt;P&gt;That will get you the fresh version of the app with the input disabled.&lt;/P&gt;</description>
    <pubDate>Thu, 22 Mar 2018 14:11:00 GMT</pubDate>
    <dc:creator>tiagofbmm</dc:creator>
    <dc:date>2018-03-22T14:11:00Z</dc:date>
    <item>
      <title>How can I disable Splunk Universals Forwarder input after installing Splunk TA_windows via deployment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-disable-Splunk-Universals-Forwarder-input-after/m-p/371931#M67511</link>
      <description>&lt;P&gt;I currently have a Splunk Universal Forwarder installed on all my servers. It was recommended by Splunk to install the TA_windows plug-in on top of the Universal Forwarder. I built out a deployment from the Search Head to deploy TA_windows add-on to my servers but I noticed the regular Universal forwarder input.conf is still active/enabled along with the TA_windows add-on.&lt;BR /&gt;
How can I disable the regular Universal Forwarder app automatically when using the TA_windows add-on.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:37:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-disable-Splunk-Universals-Forwarder-input-after/m-p/371931#M67511</guid>
      <dc:creator>jjacksonVirtus</dc:creator>
      <dc:date>2020-09-29T18:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: How can I disable Splunk Universals Forwarder input after installing Splunk TA_windows via deployment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-disable-Splunk-Universals-Forwarder-input-after/m-p/371932#M67512</link>
      <description>&lt;P&gt;Can you change that inputs.conf in the app in the deployment server and then do a splunk reload deploy server?&lt;/P&gt;

&lt;P&gt;That will get you the fresh version of the app with the input disabled.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 14:11:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-disable-Splunk-Universals-Forwarder-input-after/m-p/371932#M67512</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2018-03-22T14:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: How can I disable Splunk Universals Forwarder input after installing Splunk TA_windows via deployment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-disable-Splunk-Universals-Forwarder-input-after/m-p/371933#M67513</link>
      <description>&lt;P&gt;Please let me know if the answer was useful for you. If it was, accept it and upvote. If not, give us more input so we can help you with that&lt;/P&gt;</description>
      <pubDate>Sat, 24 Mar 2018 07:08:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-disable-Splunk-Universals-Forwarder-input-after/m-p/371933#M67513</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2018-03-24T07:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: How can I disable Splunk Universals Forwarder input after installing Splunk TA_windows via deployment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-disable-Splunk-Universals-Forwarder-input-after/m-p/371934#M67514</link>
      <description>&lt;P&gt;Keep in mind that multiple &lt;CODE&gt;input.conf&lt;/CODE&gt; is a feature and not a distraction. Meaning, each &lt;CODE&gt;input.conf&lt;/CODE&gt;brings its needs to the table and all of them are being aggregated together. So, as long as they don't conflict each other they can coexist according to the beloved - &lt;EM&gt;live and let live&lt;/EM&gt; idea.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Mar 2018 22:32:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-disable-Splunk-Universals-Forwarder-input-after/m-p/371934#M67514</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-03-24T22:32:48Z</dc:date>
    </item>
  </channel>
</rss>

